Read-only by default
Advertising connections should request reporting permissions rather than the ability to create, edit, pause or delete campaigns.
AdSpend Lens is designed around read-only permissions, encrypted credentials, strong tenant separation and clear disconnection and deletion processes.
Advertising connections should request reporting permissions rather than the ability to create, edit, pause or delete campaigns.
OAuth access and refresh tokens must be encrypted at rest and never exposed to the customer’s browser.
Every query and background job must be scoped to the correct customer, business and selected advertising account.
Dashboards should use stored data instead of calling Meta or Google every time a filter changes.
Record connection changes, sync runs, failures and important administrative actions.
Customers should be able to revoke access and request removal of stored advertising information through a defined GDPR process.
The platform is intended to retrieve permitted reporting data, creative information and account settings required for analysis.
AdSpend Lens is designed to remain read-only, transparent and removable whenever the customer decides to disconnect.